Saturday, May 30, 2015

// // Leave a Comment

Free Build up your OWN Ransomware Malware using TOX ToolKit | blog-windows Blog

Free Build up your OWN Ransomware Malware using TOX ToolKit

What is Ransomware?
Ransomware is malicious software that denies you access to your computer or files until you pay a ransom.  There are two types of ransomware that SophosLabs is commonly seeing:
Ransomware is a type of computer virus that infects a target computer, encrypts their sensitive documents and files, and locks the out until the victim pays a ransom amount, most often in Bitcoins. 


Tox — Free Ransomware Kit


Now, to spread this creepy threat more easily by even a non-tech user, one dark web hacker has released a ransomware-as-a-service kit, dubbed "Tox," for anyone to download and set up their own ransomware for free.

Yes, believe it or not, but Tox is completely free to use. The developers of the online software make money by taking a cut (20%) of any successful ransomware campaigns its users run.

Tox, which runs on TOR, requires not much technical skills to use and is designed in such a way that almost anyone can easily deploy ransomware in three simple steps, according to security researchers at McAfee who discovered the kit.

Salient Points:
  • Tox is free. You just have to register on the site.
  • Tox is dependent on TOR and Bitcoin. That allows for some degree of anonymity.
  • The malware works as advertised.
  • Out of the gate, the standard of antimalware evasion is fairly high, meaning the malware’s targets would need additional controls in place (HIPS, whitelisting, sandboxing) to catch or prevent this.
Once you register for the product, you can create your malware in three simple steps.
  • Enter the ransom amount. (The site takes 20% of the ransom.)
  • Enter your “cause.”
  • Submit the captcha.



This process creates an executable of about 2MB that is disguised as a .scr file. Then the Tox “customers” distribute and install as they see fit. The Tox site (on the TOR network) will track the installs and profit. To withdraw funds, you need only supply a receiving Bitcoin address.


Upon execution, the malware encrypts the victims’ data and prompts them for the ransom, including the Bitcoin address for sending payment.




Technical Information
Although easy to use and functional, the malware appears to lack complexity and efficiency within the code.



Tox malware portable executable sections.
The developer has left several identifying strings within the code. Examples:
  • C:/Users/Swogo/Desktop/work/tox/cryptopp/secblock.h
  • C:/Users/Swogo/Desktop/work/tox/cryptopp/filters.h
  • C:/Users/Swogo/Desktop/work/tox/cryptopp/cryptlib.h
  • C:/Users/Swogo/Desktop/work/tox/cryptopp/simple.h
Tox-generated malware is compiled in MinGW and uses AES to encrypt client files via the Crypto++ library.  The Microsoft CryptoAPI is used for key generation.
 Network Information
The malware first downloads Curl and the TOR client:
  • hxxp://www.paehl.com/open_source/?download=curl_742_1.zip
  • hxxp://dist.torproject.org/torbrowser/4.5.1/tor-win32-0.2.6.7.zip
All downloaded files and artifacts are stored in the following path:
  • C:\Users\\AppData\Roaming\
After execution, Tox will start TOR in SOCKS5 proxy mode with the following command-line parameters:
-socks5-hostname 127.0.0.1:9050 –data \


How to Protect Yourself from Ransomware Threat?


Last week, I introduced you a Free Ransomware Decryption and Malware Removal ToolKit that could help you deal with different variants of ransomware malware and unlock encrypted files without paying off a single penny to the cyber crooks.

However, there are some necessary steps that should be taken to protect yourself from Ransomware attacks.
  • Remember always to keep regular backups of your important data.
  • Make sure that you run an active anti-virus security suite of tools on your machine.
  • Do not open any email attachments from unknown sources.
  • Finally, browse the Internet safely.

Reference:

https://blogs.mcafee.com/mcafee-labs/meet-tox-ransomware-for-the-rest-of-us
http://thehackernews.com/2015/05/ransomware-creator.html


Your Good comments Encourages me to keep posting Nice Articles so keep Commenting & Sharing
Read More

Thursday, May 28, 2015

// // Leave a Comment

Top 15 Indicators Of Compromise | blog-windows Blog

Top 15 Indicators Of Compromise

Unusual account behaviours, strange network patterns, unexplained configuration changes, and odd files on systems can all point to a potential breach
In the quest to detect data breaches more quickly, indicators of compromise can act as important breadcrumbs for security pros watching their IT environments. Unusual activity on the network or odd clues on systems can frequently help organizations spot attacker activity on systems more quickly so that they can either prevent an eventual breach from happening -- or at least stop it in its earliest stages.
According to the experts, here are some key indicators of compromise to monitor (in no particular order):
1. Unusual Outbound Network Traffic
Perhaps one of the biggest telltale signs that something is amiss is when IT spots unusual traffic patterns leaving the network.
"A common misperception is that traffic inside the network is secure," says Sam Erdheim, senior security strategist for AlgoSec. "Look for suspicious traffic leaving the network. It's not just about what comes into your network; it's about outbound traffic as well."
Considering that the chances of keeping an attacker out of a network are difficult in the face of modern attacks, outbound indicators may be much easier to monitor, says Geoff Webb, director of solution strategy for NetIQ.
"So the best approach is to watch for activity within the network and to look for traffic leaving your perimeter," he says. "Compromised systems will often call home to command-and-control servers, and this traffic may be visible before any real damage is done."
2. Anomalies In Privileged User Account Activity
The name of the game for a well-orchestrated attack is for attackers to either escalate privileges of accounts they've already compromised or to use that compromise to leapfrog into other accounts with higher privileges. Keeping tabs on unusual account behavior from privileged accounts not only watches out for insider attacks, but also account takeover.
"Changes in the behavior of privileged users can indicate that the user account in question is being used by someone else to establish a beachhead in your network," Webb says. "Watching for changes -- such as time of activity, systems accessed, type or volume of information accessed -- will provide early indication of a breach."
3. Geographical Irregularities
Whether through a privileged account or not, geographical irregularities in log-ins and access patterns can provide good evidence that attackers are pulling strings from far away. For example, traffic between countries that a company doesn't do business with offers reason for pause.
"Connections to countries that a company would normally not be conducting business with [indicates] sensitive data could be siphoned to another country," says Dodi Glenn, director of security content management for ThreatTrack Security.
Similarly, when one account logs in within a short period of time from different IPs around the world, that's a good indication of trouble.
"As to data-breach clues, one of the most useful bits I've found is logs showing an account logging in from multiple IPs in a short time period, particularly when paired with geolocation tagging," says Benjamin Caudill, principal consultant for Rhino Security. "More often than not, this is a symptom of an attacker using a compromised set of credentials to log into confidential systems."
4. Other Log-In Red Flags
Log-in irregularities and failures can provide excellent clues of network and system probing by attackers.
"Check for failed logins using user accounts that don't exist -- these often indicate someone is trying to guess a user's account credentials and gain authorization," says Scott Pierson, product specialist for Beachhead Solutions, explaining that unusual numbers of failed log-ins for existing accounts should also be a red flag.
Similarly, attempted and successful log-in activity after hours can provide clues that it isn't really an employee who is accessing data.
"If you see John in accounting logging onto the system after work hours and trying to access files for which he is not authorized, this bears investigation," says A.N. Ananth, CEO of EventTracker.
5. Swells In Database Read Volume 
Once an attacker has made it into the crown jewels and seeks to exfiltrate information, there will be signs that someone has been mucking about data stores. One of them is a spike in database read volume, says Kyle Adams, chief software architect for Junos WebApp Secure at Juniper Networks.
"When the attacker attempts to extract the full credit card database, it will generate an enormous amount of read volume, which will be way higher than you would normally see for reads on the credit card tables," he says.
6. HTML Response Sizes
Adams also says that if attackers use SQL injection to extract data through a Web application, the requests issued by them will usually have a larger HTML response size than a normal request.
"For example, if the attacker extracts the full credit card database, then a single response for that attacker might be 20 to 50 MB, where a normal response is only 200 KB," he says.
7. Large Numbers Of Requests For The Same File
It takes a lot of trial and error to compromise a site -- attackers have to keep trying different exploits to find ones that stick. And when they find signs that an exploit might be successful, they'll frequently use different permutations to launch it.
"So while the URL they are attacking will change on each request, the actual filename portion will probably stay the same," Adams says. "So you might see a single user or IP making 500 requests for 'join.php,' when normally a single IP or user would only request that page a few times max."
8. Mismatched Port-Application Traffic
Attackers often take advantage of obscure ports to get around more simple Web filtering techniques. So if an application is using an unusual port, it could be sign of command-and-control traffic masquerading as "normal" application behavior.
"We have noticed several instances of infected hosts sending C&C communications masked as DNS requests over port 80," says Tom Gorup, SOC analyst for Rook Consulting. "At first glance, these requests may appear to be standard DNS queries; however, it is not until you actually look at those queries that you see the traffic going across a nonstandard port. "
9. Suspicious Registry Or System File Changes
One of the ways malware writers establish persistence within an infected host is through registry changes.
"Creating a baseline is the most important part when dealing with registry-based IOCs," Gorup says. "Defining what a clean registry is supposed to contain essentially creates the filter against which you will compare your hosts. Monitoring and alerting on changes that deviate outside the bounds of the clean 'template' can drastically increase security team response time."
Similarly, many attackers will leave behind signs that they've tampered with a host in system files and configurations, says Webb, who has seen organizations more quickly identify compromised systems by looking for these kinds of changes.
"What can happen is that the attacker will install packet-sniffing software to harvest credit card data as it moves around the network," he says. "The attacker targets a system that can watch the network traffic, then installs the harvesting tool. While the chances of catching the specific harvesting tool are slim -- because they will be targeted and probably not seen before -- there is a good chance to catch the changes to the system that houses the harvesting tool."
10. DNS Request Anomalies
According to Wade Williamson, senior security analyst for Palo Alto Networks, one of the most effective red flags an organization can look for are telltale patterns left by malicious DNS queries.
"Command-and-control traffic is often the most important traffic to an attacker because it allows them ongoing management of the attack and it needs to be secure so that security professionals can't easily take it over," he says. "The unique patterns of this traffic can be recognized and is a very standard approach to identifying a compromise."
Gorup agrees that DNS exfiltration can be "extremely loud."
"Seeing a large spike in DNS requests from a specific host can serve as a good indicator of potentially suspect activity," he says. "Watching for patterns of DNS requests to external hosts, compared against geoIP and reputation data, and implementing appropriate filtering can help mitigate C&C over DNS."
11. Unexpected Patching Of Systems
Patching is generally a good thing, but if a system is inexplicably patched without reason, that could be the sign that an attacker is locking down a system so that other bad guys can't use it for other criminal activity.
"Most attackers are in the business of making money from your data -- they certainly don't want to share the profits with anyone else," Webb says. "It sometimes does pay to look security gift horses in the mouth."
12. Mobile Device Profile Changes
As attackers migrate to mobile platforms, enterprises should keep an eye on unusual changes to mobile users' device settings. They also should watch for replacement of normal apps with hostile ones that can carry out man-in-the-middle attacks or trick users into giving up their enterprise credentials.
"If a managed mobile device gains a new configuration profile that was not provided by the enterprise, this may indicate a compromise of the user's device and, from there, their enterprise credentials," says Dave Jevans, founder and CTO of Marble Security. "These hostile profiles can be installed on a device through a phishing or spear-phishing attack."
13. Bundles Of Data In The Wrong Places
According to EventTracker's Ananth, attackers frequently aggregate data at collection points in a system before attempting exfiltration.
"If you suddenly see large gigabytes of information and data where they should not exist, particularly compressed in archive formats your company doesn't' use, this is a telltale sign of an attack," he says.
In general, files sitting around in unusual locations should be scrutinized because they can point to an impending breach, says Matthew Standart, director of threat intelligence at HBGary.
"Files in odd places, like the root folder of the recycle bin, are hard to find looking through Windows, but easy and quick to find with a properly crafted Indicator of Compromise [search]," Standart says. "Executable files in the temp folder is another one, often used during privilege escalation, which rarely has a legitimate existence outside of attacker activity."
14. Web Traffic With Unhuman Behavior
Web traffic that doesn't match up with normal human behavior shouldn't pass the sniff test, says Andrew Brandt, director of threat research for Blue Coat.
"How often do you open 20 or 30 browser windows to different sites simultaneously? Computers infected with a number of different click-fraud malware families may generate noisy volumes of Web traffic in short bursts," he says." Or, for instance, on a corporate network with a locked-down software policy, where everyone is supposed to be using one type of browser, an analyst might see a Web session in which the user-agent string which identifies the browser to the Web server indicates the use of a browser that's far removed from the standard corporate image, or maybe a version that doesn't even exist."
15. Signs Of DDoS Activity
Distributed denial-of-service attacks (DDoS) are frequently used as smokescreens to camouflage other more pernicious attacks. If an organization experiences signs of DDoS, such as slow network performance, unavailability of websites, firewall failover, or back-end systems working at max capacity for unknown reasons, they shouldn't just worry about those immediate problems.
"In addition to overloading mainstream services, it is not unusual for DDoS attacks to overwhelm security reporting systems, such as IPS/IDS or SIEM solutions," says Ashley Stephenson, CEO at Corero Network Security. "This presents new opportunities for cybercriminals to plant malware or steal sensitive data. As a result, any DDoS attack should also be reviewed for related data breach activity."
Reference:

Your Good comments Encourages me to keep posting Nice Articles so keep Commenting & Sharing
Read More
// // Leave a Comment

About Netwire RAT | blog-windows Blog


Hello Guys, While doing research I got valuable information about Netwire RAT.
I am gonna sharing it with you.

Note: Do Not Ask About the Setup because,
1. Most of the Hacker/Attacker bind it with Malware.
2. Almost all RAT Setup are detectable as Malware by All Anti-Virus.

Happy Hunting Guys :)

The Attack
This recent attack used a specially crafted Word document with an embedded malicious macro. An attacker might also use social-engineering tricks to lure victims into opening the malicious document.
Once the document is opened, the exploit downloads Netwire from Dropbox:
hxxp://www.dropbox.com/s/q*********/tcpview.exe?dl=1
Once executed, the malware tcpview.exe copies itself to the AppData folder. By using trusted storage sites such as Dropbox the malware can sometimes avoid firewall and heuristic detection.

Netwire

Netwire is a multiplatform remote administration tool (RAT) widely used by cybercriminals since 2012. Netwire provides attackers with various functions to remotely control infected machines.


Lately, McAfee Labs has seen a spike in the number of attacks employing Netwire. In a recent case, Netwire was used in a targeted attack involving banking and healthcare sectors.
 Netwire is a sophisticated RAT with various remote-control functions, including:
·         Collecting system information
·         File manager
·         System manager
·         Keylogging and screen capture

The following screen capture shows Netwire’s host-monitoring tool:


The file tcpview.exe is obfuscated with a custom cryptor. The malware also creates a start-up entry in the registry for persistence.


The Netwire client tcpview.exe is signed by fake and invalid digital certificates.




The second stage of the attack involves a Netwire backdoor connecting to the following control servers:
·         davidluciano.mooo.com
·         jydonky.mooo.com
·         papybrown.mooo.com
Mooo.com is a dynamic DNS domain provider often favored by Netwire attackers. Currently all these domains point to the following IP addresses in the United States:
·         216.38.7.229
·         23.105.131.179
·         23.105.131.236


The malicious Word document is detected by McAfee Advanced Threat Defense with high severity.






Advanced Threat Defense also classifies the downloaded file as malicious.


Reference:
https://blogs.mcafee.com/mcafee-labs/netwire-rat-behind-recent-targeted-attacks


For Your Knowledge:

All About Netwire


Your Good comments Encourages me to keep posting Nice Articles so keep Commenting & Sharing.



Read More

Wednesday, May 27, 2015

// // Leave a Comment

Tukang Hutang Yang Model Begini Harus Dimusnahkan Dari Bumi

Katanya, orang pelit itu kuburannya sempit. Menurut gue, pelit atau nggak pelit, kuburannya mah bakal sempit. Paling ukurannya cuma 2x1 meter. Mana ada yang ukuran kuburannya 3 hektar dilengkapi dapur, kolam renang dan gym? 

Tapi meskipun gue nggak percaya mitos itu, gue juga tetep nggak mau jadi orang pelit. Setiap ada temen butuh bantuan, sebisa mungkin gue tolong. Karena gue percaya bahwa ada karma baik maupun karma buruk. Masalahnya, banyak orang yang abis dibantu malah lupa atau sok lupa. Seakan-akan mereka abis disrempet roket Rusia tepat di kepala, dan Amnesia.

Akhir-akhir ini gue gedeg banget. Gue pernah punya temen banyak. Kita sering barengan dalam suka duka. Nongkrong bareng, jalan bareng, atau bahkan nginep bareng-bareng. Tapi akhir-akhir ini, gue hampir nggak punya temen nongkrong lagi. Pada ke mana temen-temen gue? Pada kabur. Ngilang.

Kenapa mereka ngilang? Nggak.. Mereka nggak meninggal, atau sibuk nanem padi di gurun Sahara kok. Mereka ngilang setelah mereka ngutang. Iya, ada yang sengaja menjauh, ada yang sengaja menghilang sama sekali. Ntah karena malu nggak bisa bayar hutang, atau memang nggak mau bayar hutang. Hal ini yang bikin gue suka mendadak emosi kalo ada temen lain yang kesusahan terus bilang mau ngutang. Gue trauma, jangan-jangan abis gue pinjemin duit, dia juga ngilang? Gue udah kenyang dengan realita kehilangan teman gara-gara utang. Nyokap gue pernah bilang,

"Kalo temenmu meninggalkanmu setelah mereka ngutang ke kamu, artinya mereka menghargai pertemanan kalian dengan uang segitu. Nggak apa-apa kehilangan teman yang kayak gitu."

Emang sih, gapapa kehilangan temen yang brengsek. Tapi punya temen-temen brengsek, kadang terasa lebih baik daripada nggak punya temen sama sekali. Hidup terasa sepi. :(

Oke, berdasarkan fakta-fakta yang udah gue alamin, gue mau sharing kepada kalian bagaimana etikanya orang yang punya hutang. Biar kalian nggak dicap sebagai makhluk yang nggak tau terima kasih maupun nggak bertanggung jawab, sebaiknya jangan sampai jadi tukang hutang yang begini:

Nggak Bayar
Minjem uang dan akhirnya dipinjemin pas butuh itu rasanya emang menyenangkan. Tapi sebagian orang lupa mengartikan hal itu. Mereka salah mengartikan antara "dipinjemin" dan "dikasih". Jadinya, pas mereka udah punya duit, mereka nggak kepikiran buat balikin uang yang mereka pinjem.

Dan yang paling sering kejadian, orang suka lupa mereka ngutang kalo cara mereka minjem adalah dengan kalimat, "Tolong beliin pake duit lo dulu ya~"

Hayo.. Siapa yang pernah ngelakuin hal serupa? :p

Nggak Ngabarin
Sebenernya gue adalah tipe orang yang nggak bakal rewel pas temen ngutang duit. Gue nggak bakal ngejar-ngejar atau nagih-nagih. Tapi dengan catatan, orangnya rajin ngabarin kalo dia belum mampu balikin duitnya. Dengan mengakui hal itu, gue bisa narik kesimpulan bahwa dia masih inget akan hutangnya. Gue masih bisa mempercayai dia.


Nah, kalo orangnya nggak pernah ngabarin atau sok lupa dengan hutangnya, tentu bikin gue khawatir dong. Kalo gue ingetin, gue dikira nagih. Tapi kalo nggak diingetin, orangnya juga melanjutkan hidup dengan damai. Rasanya kayak pengin bikinin tattoo di jidatnya bertuliskan, "Bayar utang lo ya!"

Apa sih susahnya bilang, "Hey bro.. Maaf ya, harusnya hari ini aku bayar hutang, tapi ternyata belum ada uangnya. Aku janji, minggu depan aku bayar ya~"?

Kalimat sesimpel itu kalo diucapin sebelum ditagih/diingetin, udah cukup membuat si pemilik uang ngerasa tenang kok. Karena kalimat itu menunjukkan kalo yang ngutang itu masih mengingat tanggung jawabnya kepada si pemilik uang.

Tetep Bisa Pamer
Pernah nggak, lo ngalamin punya temen yang ngutang ke elo, tiap ditagih dia bilang belum punya, tapi ternyata dia upload foto-foto belanjaannya di sosial media? 


Gue juga pernah ngalamin hal serupa. Pas dia pamer belanjaannya di Facebook, gue screenshoot chat dia yang berisi permohonan maaf karena belum bisa bayar hutang, terus gue upload ke kolom komentarnya. Endingnya gue di-unfriend.

Mbok orang kalo masih ngerasa punya hutang ke orang tuh hormatin orang yang udah bantuin to. Kalopun belum niat balikin, ya jangan pamer-pamer lah. Jangan jadi makhluk bermuka dua, melas-melas pas ditagih, tapi tetep rajin belanja dengan gigih. Kok bisa sih, bangga mamerin harta hasil nipu orang-orang yang sudah memberikan kepercayaannya?

Lebih Galak
Wajarnya, orang yang minjemin duit itu harusnya lebih tegas kepada orang yang minjem. Soalnya orang yang minjemin itu punya hak untuk menuntut tanggung jawab dari si peminjam. Tapi pada prakteknya, banyak peminjam yang lebih galak daripada si pemilik uang pas ditagih. Mulai dari kalimat, "Lo kok perhitungan banget sih?! Temen macam apa lo?!"

Sampai kalimat, "EMANG GUE PUNYA UTANG YA? KAPAN? MANA BUKTINYA? JANGAN FITNAH LO YA! GUE LAPORIN POLISI NIH!"

Makhluk kayak gini sebaiknya dikubur di liang lahat dengan ukuran 50cm x 50cm posisi kayang.

Ngilang
Ini tipe tukang hutang yang paling menyebalkan buat gue. Modus mereka: Deketin-> Baikin -> Ngutang -> Kabur -> Nyari temen lain -> Baikin -> Ngutang -> Kabur -> Gitu terus siklusnya sampai ISIS bikin markas di Bulan.

Tipe tukang ngutang yang kayak gini bener-bener bikin gue takut untuk berteman, dan takut buat bantuin temen yang butuh duit lagi. Gara-gara orang yang kayak gini, gue selalu suudzon tiap ada temen bilang butuh duit. Jadi, tiap ada temen bilang mau ngutang, gue nganggep itu adalah cara pamitan mereka. Soalnya yang sering kejadian, kalo pas mau ngutang mereka tuh ngemis-ngemis sepenuh hati, tapi abis dihutangi mereka bakal ngilang ditelan bumi.

Saran gue buat kalian yang punya temen semacam ini, sadarin aja mereka. Jangan ragu buat nagih hak lo. Mulai dari cara yang baik-baik, dengan ngomong pelan-pelan dari hati ke hati. Kalo mereka nggak mau beritikad baik juga, pake jalan yang rese juga gapapa. Kan itu pilihan mereka sendiri. Tagih di sosial media, di chat, di kolom komentar, tagih pas ketemu, tagih via pengumuman radio, bebas. Kadang untuk mengalahkan orang yang rese, kita harus lebih rese. :p


Tapi berkat orang-orang yang kayak gini, gue jadi belajar. Saat ada temen mau ngutang, gue nggak bakal ngasih uang dengan jumlah sesuai permintaannya. Gue bakal ngasih uang dengan jumlah yang bisa gue ikhlasin kalo nggak balik aja. Jadinya kalo pun tuh orang nggak balikin duitnya gue nggak nyesek-nyesek amat, dan silaturahmi tetep terjaga karena gue nggak dicap pelit.

Buat yang suka ngutang dan rese, inget ye.. Kalo lo suka nunda hak orang lain, Tuhan juga nggak bakal segan-segan buat nunda hak lo untuk berbahagia. Sekali lo pernah ngecewain orang yang mau bantuin elo, jangan nyesel kalo lain kali dia nggak mau bantuin lo lagi meski lo dapet musibah yang lebih ngeri. Soalnya kepercayaan itu kayak tulang angkle, sekali pernah cidera, nggak bisa pulih seperti semula. Lagian kenapa sih, lebih milih hidup dengan penuh rasa sungkan, khawatir, dan takut ketemu orang karena banyak hutang demi kesenangan sesaat doang? Please remember..

Karma is a bitch. It would force you to pay, after you have enough fun!

Yap.. Itu aja uneg-uneg gue sekarang. Makasih udah nyempetin waktu berharganya buat baca tulisan ini. Kalo kalian pernah ngalamin hal serupa sama tukang hutang rese, silakan share di kolom komentar ya!
Read More